Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD published the first details for CVE-2023-4474
Feedly found the first article mentioning CVE-2023-4474. See article
EPSS Score was set to: 0.1% (Percentile: 41.3%)
This CVE started to trend in security discussions
The vulnerability CVE-2023-4474 is a critical blind OS command injection vulnerability in Zyxel devices. It has been assigned a CVE score but there is no information provided on its criticality. It is unclear if the vulnerability has been exploited in the wild or if there are any proof-of-concept exploits available. It is recommended to check for any available mitigations, detections, or patches from Zyxel to address this vulnerability. There is no information provided on any downstream impacts to other third-party vendors or technology. See article
Detection for the vulnerability has been added to Qualys (731667)